{"id":"MAL-2026-13441","summary":"Malicious code in consumerweb-creditcollection (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (d1d673b014d7769d23ec9252c38424a3d1e2b400756cafa605f65383d93da348)\nconsumerweb-creditcollection@99.9.1 is a hollow package whose main index.js exports an empty object. Its sole runtime effect is pulling in a dependency `ltidisafe` pinned to an arbitrary tarball URL on a third-party Google Cloud Storage bucket (`https://ltidi.storage.googleapis.com/depenconf/ltidisafe-3.5.3.tgz`) rather than an npm registry entry. Installing this package causes npm to download and install code from that off-registry URL, which is outside npm registry scanning. The `depenconf` path segment, the internal-sounding package name, and the high version number 99.9.1 are consistent with a dependency-confusion / namespace-squat delivery vector where the lure package's only purpose is to force resolution of attacker-hosted code into the installer's dependency tree.\n","modified":"2026-08-06T23:50:08.626587199Z","published":"2026-08-06T16:18:36Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-06T16:18:36Z","sha256":"d1d673b014d7769d23ec9252c38424a3d1e2b400756cafa605f65383d93da348","source":"amazon-inspector","versions":["99.9.1"],"id":"IN-MAL-2026-016671","import_time":"2026-08-06T18:09:03.984797741Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/consumerweb-creditcollection/v/99.9.1"}],"affected":[{"package":{"name":"consumerweb-creditcollection","ecosystem":"npm","purl":"pkg:npm/consumerweb-creditcollection"},"versions":["99.9.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/consumerweb-creditcollection/MAL-2026-13441.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"tlsh":"7be07d204a2066334ec911f2482b619bf3708e8f0404bc0c6edf042c41aca732cf935c","path":"package.json","sha256":"067d8a16b2d3fd4f9782d2e045b5a337f30c1b0c85e3936bd5a5956838f7b7af"}],"package_integrity":[{"hashes":{"sha1":"0b27dd11d73576effed208f751e696e11c5cde90","sha512_sri":"sha512-ugY7+J7m7mA/Qg6F6IBLZH2hOu3so54/dFqfjLYOIJkOV2E5LlfdAdPSiQa8EVdO36GZPhiCcWclQT6M1rm4aQ=="},"filename":"consumerweb-creditcollection-99.9.1.tgz"}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}